Brocade Web Tools Administrator's Guide - Supporting Fabric OS v7.0.0 (53-1002152-01, March 2012)

196 Web Tools Adminstrators Guide
53-1002152-01
RADIUS management
16
4. Select a permission for the host from the Access Control List menu.
Options are Read Only and Read Write.
5. Click Apply.
RADIUS management
Fabric OS supports RADIUS authentication, authorization, and accounting service (AAA). When
configured for RADIUS, the switch becomes a Network Access Server (NAS) that acts as a RADIUS
client. In this configuration, authentication records are stored in the RADIUS host server database.
Login and logout account name, assigned role, and time accounting records are also stored on the
RADIUS server.
You should set up RADIUS through a secure connection such as SSH.
The following are the three choices in the drop-down menu when RADIUS is selected as the primary
service:
Switch Database when RADIUS Authentication Fails—When selected, the switch user login
database is checked whenever RADIUS authentication fails.
Switch Database When RADIUS Times Out—Switch user login database is checked only if the
physical connection to the RADIUS server fails.
None—Switch user login database is never checked. Only a RADIUS server can be used for
authentication.
If the switch database is selected as primary, there is no secondary option. The RADIUS server
cannot be configured as a backup for the switch user login database.
When the primary AAA service is RADIUS, you have three secondary service choices:
None
Switch Database when RADUIS authorization fails
Switch Database when RADIUS times out
When RADIUS login fails, even though RADIUS server is available, the additional service allows you
the option to use the Switch Database as backup authentication service when the RADIUS server is
not available. Alternatively, you can have no secondary AAA service, which means that only the
primary service is used for authentication.
Use the AAA Service tab of the Switch Administration window to manage RADIUS.
Enabling and disabling RADIUS
At least one RADIUS server must be configured before you can enable RADIUS.
To enable or disable RADIUS, perform the following steps.
1. Open the Switch Administration window as described in “Opening the Switch Administration
window” on page 33.
2. Select the AAA Service tab.
3. To enable RADIUS, select RADIUS from the Primary AAA Service drop-down menu.
4. Select None, Switch Database when RADIUS Login Failed, or Switch Database when RADIUS
Login Timeout from the Secondary AAA Service menu.